diff --git a/.github/workflows/ci-warm-caches.yml b/.github/workflows/ci-warm-caches.yml index fcc2dccec9a..b17f75f3101 100644 --- a/.github/workflows/ci-warm-caches.yml +++ b/.github/workflows/ci-warm-caches.yml @@ -49,6 +49,12 @@ concurrency: group: warm-caches-${{ github.ref }} cancel-in-progress: true +env: + # Pull and tag images straight from Docker Hub, never through registry.defectdojo.com: + # the images CI built itself are tagged defectdojo/... (= docker.io/defectdojo/...), and CI + # pulls must not count as installs. + DD_IMAGE_REGISTRY: docker.io + jobs: warm-migrated-db: name: Warm Migrated Database Snapshot diff --git a/.github/workflows/fetch-oas.yml b/.github/workflows/fetch-oas.yml index 669a3dc0003..4f039034711 100644 --- a/.github/workflows/fetch-oas.yml +++ b/.github/workflows/fetch-oas.yml @@ -11,6 +11,10 @@ on: required: true env: + # Pull and tag images straight from Docker Hub, never through registry.defectdojo.com: + # the images CI built itself are tagged defectdojo/... (= docker.io/defectdojo/...), and CI + # pulls must not count as installs. + DD_IMAGE_REGISTRY: docker.io release_version: ${{ github.event.inputs.version || github.event.inputs.release_number }} jobs: diff --git a/.github/workflows/integration-tests.yml b/.github/workflows/integration-tests.yml index 0d921869ee6..5e77e61daf7 100644 --- a/.github/workflows/integration-tests.yml +++ b/.github/workflows/integration-tests.yml @@ -3,6 +3,12 @@ name: Integration tests on: workflow_call: +env: + # Pull and tag images straight from Docker Hub, never through registry.defectdojo.com: + # the images CI built itself are tagged defectdojo/... (= docker.io/defectdojo/...), and CI + # pulls must not count as installs. + DD_IMAGE_REGISTRY: docker.io + jobs: integration_tests: # run tests with docker compose diff --git a/.github/workflows/performance-tests.yml b/.github/workflows/performance-tests.yml index 1dec1d8f14e..fd379a15c7a 100644 --- a/.github/workflows/performance-tests.yml +++ b/.github/workflows/performance-tests.yml @@ -3,6 +3,12 @@ name: Performance Tests on: workflow_call: +env: + # Pull and tag images straight from Docker Hub, never through registry.defectdojo.com: + # the images CI built itself are tagged defectdojo/... (= docker.io/defectdojo/...), and CI + # pulls must not count as installs. + DD_IMAGE_REGISTRY: docker.io + jobs: performance-tests: name: Performance Tests diff --git a/.github/workflows/rest-framework-tests.yml b/.github/workflows/rest-framework-tests.yml index 0b79a45b128..f6303adf0b3 100644 --- a/.github/workflows/rest-framework-tests.yml +++ b/.github/workflows/rest-framework-tests.yml @@ -10,6 +10,12 @@ on: type: boolean default: false +env: + # Pull and tag images straight from Docker Hub, never through registry.defectdojo.com: + # the images CI built itself are tagged defectdojo/... (= docker.io/defectdojo/...), and CI + # pulls must not count as installs. + DD_IMAGE_REGISTRY: docker.io + jobs: unit_tests: name: Rest Framework Unit Tests diff --git a/docker-compose.yml b/docker-compose.yml index db0cfa2f264..54b93d77b48 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -11,7 +11,7 @@ services: build: context: ./ dockerfile: "Dockerfile.nginx-alpine" - image: "defectdojo/defectdojo-nginx:${NGINX_VERSION:-latest}" + image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-nginx:${NGINX_VERSION:-latest}" depends_on: uwsgi: condition: service_started @@ -35,7 +35,7 @@ services: context: ./ dockerfile: "Dockerfile.django-${DEFECT_DOJO_OS:-debian}" target: release - image: "defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}" + image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}" depends_on: initializer: condition: service_completed_successfully @@ -60,7 +60,7 @@ services: target: /app/docker/extra_settings - "defectdojo_media:${DD_MEDIA_ROOT:-/app/media}" celerybeat: - image: "defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}" + image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}" depends_on: initializer: condition: service_completed_successfully @@ -81,7 +81,7 @@ services: source: ./docker/extra_settings target: /app/docker/extra_settings celeryworker: - image: "defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}" + image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}" depends_on: initializer: condition: service_completed_successfully @@ -103,7 +103,7 @@ services: target: /app/docker/extra_settings - "defectdojo_media:${DD_MEDIA_ROOT:-/app/media}" initializer: - image: "defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}" + image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}" depends_on: postgres: condition: service_started diff --git a/readme-docs/DOCKER.md b/readme-docs/DOCKER.md index a9c705cf5d3..c1f227b9adb 100644 --- a/readme-docs/DOCKER.md +++ b/readme-docs/DOCKER.md @@ -82,7 +82,7 @@ docker compose build nginx > **_NOTE:_** It's possible to add extra fixtures in folder "/docker/extra_fixtures". ## Run with Docker Compose in release mode -To run the application based on previously built image (or based on dockerhub images if none was locally built), run: +To run the application based on previously built image (or based on the published images if none was locally built, see [Image registry](#image-registry)), run: ```zsh docker/setEnv.sh release @@ -227,6 +227,21 @@ aedc404d6dee defectdojo/defectdojo-nginx:1.0.0 "/entrypoint-nginx.sh" ... ``` +## Image registry +`docker-compose.yml` pulls the DefectDojo images through `registry.defectdojo.com`. It redirects every +request to the same images on Docker Hub (`hub.docker.com/u/defectdojo`); no image is stored or changed +there. Each pull is logged (time, image, tag, client and the requesting network) so the project can see where +DefectDojo is installed. + +To pull straight from Docker Hub, or from your own mirror, set `DD_IMAGE_REGISTRY` before running Docker Compose: + +```zsh +export DD_IMAGE_REGISTRY=docker.io # Docker Hub +export DD_IMAGE_REGISTRY=mirror.example.com # or your own registry mirror +``` + +Images you build locally are tagged with the same name, so building and running works the same either way. + ## Clean up Docker Compose Removes all containers